<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The other steveb - Steve Banks' Blog on SBS, EBS, and other Small Business Technology Topics : Phishing</title><link>http://msmvps.com/blogs/steveb/archive/tags/Phishing/default.aspx</link><description>Tags: Phishing</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Microsoft NEVER sends updates through e-mail</title><link>http://msmvps.com/blogs/steveb/archive/2008/10/11/microsoft-never-sends-updates-through-e-mail.aspx</link><pubDate>Sat, 11 Oct 2008 17:27:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1650574</guid><dc:creator>steveb</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/steveb/rsscomments.aspx?PostID=1650574</wfw:commentRss><comments>http://msmvps.com/blogs/steveb/archive/2008/10/11/microsoft-never-sends-updates-through-e-mail.aspx#comments</comments><description>&lt;p&gt;This just came through to my inbox.&amp;nbsp; Fortunately, Small Business Server 2003&amp;#39;s Exchange filtering snagged the executable but thought this is worth touching on.&amp;nbsp; Never run an executable from anyone you haven&amp;#39;t explicitly requested it from.&lt;/p&gt;
&lt;p&gt;You can see from the headers of this message that it really came from a Yahoo mail server, not Microsoft.&amp;nbsp; I found this one interesting that they are beginning to fake out the PGP key and even took the time to use Steve Lipner&amp;#39;s name in it.&amp;nbsp; Pretty creative, but still a bunch of baloney. - Steve&lt;/p&gt;
&lt;p&gt;Microsoft Mail Internet Headers Version 2.0&lt;br /&gt;thread-index: Ackrxj/LwJkXJhdjTIq3Bk8lpONEJw==&lt;br /&gt;Received: from static235-3.adsl.no ([213.161.235.3]) by corp.banksnw.com with Microsoft SMTPSVC(6.0.3790.3959); Sat, 11 Oct 2008 10:24:41 -0700&lt;br /&gt;Received: from [213.161.235.3] by b.mx.mail.yahoo.com; Sat, 11 Oct 2008 18:24:42 +0100&lt;br /&gt;Message-ID: &amp;lt;&lt;a href="mailto:01c92bce$a0ee5100$03eba1d5@03DNAG1"&gt;01c92bce$a0ee5100$03eba1d5@03DNAG1&lt;/a&gt;&amp;gt;&lt;br /&gt;From: &amp;quot;Microsoft High-priority update&amp;quot; &amp;lt;&lt;a href="mailto:customerservice@microsoft.com"&gt;customerservice@microsoft.com&lt;/a&gt;&amp;gt;&lt;br /&gt;To: &amp;lt;&lt;a href="mailto:steve@banksnw.com"&gt;steve@banksnw.com&lt;/a&gt;&amp;gt;&lt;br /&gt;Content-Transfer-Encoding: 7bit&lt;br /&gt;Subject: Security Update for OS Microsoft Windows&lt;br /&gt;Date: Sat, 11 Oct 2008 18:24:42 +0100&lt;br /&gt;MIME-Version: 1.0&lt;br /&gt;Content-Type: multipart/mixed;&lt;br /&gt;&amp;nbsp;boundary=&amp;quot;----=_NextPart_000_0006_01C92BCE.A0EE5100&amp;quot;&lt;br /&gt;Content-Class: urn:content-classes:message&lt;br /&gt;X-Priority: 3&lt;br /&gt;Importance: normal&lt;br /&gt;Priority: normal&lt;br /&gt;X-MSMail-Priority: Normal&lt;br /&gt;X-Mailer: Microsoft Outlook Express 4.72.2106.4&lt;br /&gt;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.4325&lt;br /&gt;Return-Path: &amp;lt;&lt;a href="mailto:03DNAG1@yahoo.com"&gt;03DNAG1@yahoo.com&lt;/a&gt;&amp;gt;&lt;br /&gt;X-OriginalArrivalTime: 11 Oct 2008 17:24:42.0354 (UTC) FILETIME=[3F5FED20:01C92BC6]&lt;br /&gt;X-TM-AS-Product-Ver: SMEX-7.5.0.1243-5.5.1027-16212.000&lt;br /&gt;X-TM-AS-Result: No--22.286100-5.000000-31&lt;br /&gt;X-TM-AS-User-Approved-Sender: No&lt;br /&gt;X-TM-AS-User-Blocked-Sender: No&lt;/p&gt;
&lt;p&gt;------=_NextPart_000_0006_01C92BCE.A0EE5100&lt;br /&gt;Content-Type: text/plain;&lt;br /&gt;&amp;nbsp;charset=&amp;quot;Windows-1252&amp;quot;&lt;br /&gt;Content-Transfer-Encoding: 7bit&lt;/p&gt;
&lt;p&gt;------=_NextPart_000_0006_01C92BCE.A0EE5100&lt;br /&gt;Content-Type: text/plain;&lt;br /&gt;&amp;nbsp;name=&amp;quot;RemovedAttachments002.txt&amp;quot;&lt;br /&gt;Content-Transfer-Encoding: base64&lt;br /&gt;Content-Disposition: attachment;&lt;br /&gt;&amp;nbsp;filename=&amp;quot;RemovedAttachments002.txt&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;------=_NextPart_000_0006_01C92BCE.A0EE5100--&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;-----Original Message-----&lt;br /&gt;From: Microsoft High-priority update [mailto:customerservice@microsoft.com] &lt;br /&gt;Sent: Saturday, October 11, 2008 10:25 AM&lt;br /&gt;To: Steven Banks&lt;br /&gt;Subject: Security Update for OS Microsoft Windows&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;Dear Microsoft Customer,&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;Please notice that Microsoft company has recently issued a Security Update for OS Microsoft Windows. The update applies to the following OS versions: Microsoft Windows 98, Microsoft Windows 2000, Microsoft Windows Millenium, Microsoft Windows XP, Microsoft Windows Vista.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;Please notice, that present update applies to high-priority updates category. In order to help protect your computer against security threats and performance problems, we strongly recommend you to install this update.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;Since public distribution of this Update through the official website http://www.microsoft.com would have result in efficient creation of a malicious software, we made a decision to issue an experimental private version of an update for all Microsoft Windows OS users.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;As your computer is set to receive notifications when new updates are available, you have received this notice.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;In order to start the update, please follow the step-by-step instruction:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;1. Run the file, that you have received along with this message.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;2. Carefully follow all the instructions you see on the screen.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;If nothing changes after you have run the file, probably in the settings of your OS you have an indication to run all the updates at a background routine. In that case, at this point the upgrade of your OS will be finished.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;We apologize for any inconvenience this back order may be causing you.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;Thank you,&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;Steve Lipner&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;Director of Security Assurance&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;Microsoft Corp.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;-----BEGIN PGP SIGNATURE-----&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;Version: PGP 7.1&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;font-family:Arial;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;TLG52OUNH1ZE78UC9M3JL34R9RXTPT38TDP3DK09RJJ1E9305S400UA96V8NEVBPT&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;Y57343V8GJE4SL8JM3J39GAKNRK82WRH19IF566HLV8AM3SOCE52M12LHS9NKH899&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;J512NAX08TP9LE56GCNX3CN39AKLV44YKA2RYUMRK442ISYAQKYG85J5UN41TW5G4&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;C92RNORH2JFSI7SCIOBDDAWPTL8JO9VXH3XSE4S7SJO33XCED3YUAB8ZGJ4GCOBP3&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;8JLFYB93MBKN1SSL2ZMKIFB8619TDPDJEEY==&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:x-small;"&gt;&lt;span style="font-family:Arial;"&gt;-----END PGP SIGNATURE-----&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1650574" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/steveb/archive/tags/UCE/default.aspx">UCE</category><category domain="http://msmvps.com/blogs/steveb/archive/tags/SPAM/default.aspx">SPAM</category><category domain="http://msmvps.com/blogs/steveb/archive/tags/Phishing/default.aspx">Phishing</category></item></channel></rss>